Temporal Key Integrity Protocol (TKIP)

The interim Wi-Fi encryption protocol of WPA, which wrapped WEP's RC4 cipher in per-packet key mixing and an integrity check so existing hardware could be upgraded. Now deprecated.

Temporal Key Integrity Protocol was designed as an urgent repair for Wired Equivalent Privacy (WEP) once WEP’s weaknesses were public. It had to run on the Wi-Fi hardware already in service, so it kept WEP’s RC4 stream cipher and could reach many devices through a firmware update. It then added what WEP lacked: a key mixed afresh for every packet, a sequence counter that rejects replayed frames, and a message integrity check called Michael. It shipped as the encryption of WPA and was also defined in the IEEE 802.11i amendment, alongside CCMP. NIST SP 800-97 describes both.

CCMP, built on AES, became the required encryption of WPA2 and is the stronger design; SP 800-97 notes that only CCMP rests on a FIPS-approved algorithm. Attacks on TKIP were published from 2008 onwards, the IEEE later deprecated it, and WPA3 does not use it. A network that still allows TKIP in a mixed mode for old clients keeps that weakness for every client that negotiates it.

Exam relevance: a scenario may list wireless options and ask which is the weakest after WEP, or which one was built for hardware that could not run AES. Candidates are expected to place TKIP with WPA and RC4 as a transitional fix, and CCMP with WPA2 and AES as its replacement.